- Download the European Commission press release here.
The European Commission has designated ChatGPT as a Very Large Online Search Engine (VLOSE), while Reddit and Roblox have been designated as Very Large Online Platforms (VLOPs) under the Digital Services Act (DSA). The three services declared that they reach at least 45 million average monthly users in the EU, meeting the threshold for designation.
ChatGPT qualifies as a hybrid service and an online search engine because it responds to prompts and can search the web. Reddit and Roblox qualify as online platforms because users can publish and share content. Following the designations, the companies have four months, until January 2027, to comply with additional DSA obligations.
ChatGPT, Reddit and Roblox must identify, analyse and assess systemic risks arising from the design or functioning of their services, related systems and how users make use of them. They must assess these risks at least once a year. They must also conduct an assessment before deploying functionality likely to have a critical impact on identified risks. The assessment must consider:
- The dissemination of illegal content.
- Negative effects on fundamental rights, including privacy, data protection, freedom of expression, non-discrimination and children’s rights.
- Negative effects on civic discourse, electoral processes and public security.
- Risks involving gender-based violence, public health and minors, including serious effects on physical and mental wellbeing.
They must also assess how their recommender and other algorithmic systems, content moderation, terms and conditions, advertising systems and data practices affect those risks. This assessment must cover intentional manipulation, including inauthentic use and automated exploitation. It must also consider the rapid amplification of illegal or prohibited content, as well as regional and linguistic factors.
The companies must retain supporting documents for these assessments for at least three years. They must provide them to the Commission or the relevant Digital Services Coordinator when requested.
Mitigating the risks: They must then put in place reasonable, proportionate and effective measures tailored to the risks identified. The DSA lists measures including:
- Changing the design, features or functioning of the service and its interface.
- Changing terms and conditions and how they are enforced.
- Adjusting content moderation processes, including the speed and quality of notices and, where appropriate, removal of illegal content.
- Testing and adapting algorithmic and recommender systems.
- Adjusting advertising systems and limiting or changing how advertisements are presented.
- Strengthening internal processes, resources, testing, documentation and oversight.
- Working with trusted flaggers and other platforms through relevant codes of conduct and crisis protocols.
- Giving users more information through awareness measures and interface changes.
- Taking targeted measures to protect children, including age verification, parental controls and tools for reporting abuse or obtaining support.
- Marking generated or manipulated images, audio and video that falsely appear authentic, while providing users with a tool to flag such material.
Recommender systems and data access: All three platforms must provide at least one option for each recommender system that is not based on profiling. The companies must also provide the Commission or the relevant Digital Services Coordinator with access to data needed to monitor compliance.
When requested, it must explain the design, logic, functioning and testing of its algorithmic systems, including recommender systems. Vetted researchers can also request access to relevant data to study systemic risks and assess the effectiveness and impact of mitigation measures.
Audits and compliance: The companies need to conduct an independent audit at least once a year, at its own expense. The audit covers its obligations under the Act and any commitments it makes under relevant codes of conduct or crisis protocols. They must give auditors access to relevant data and premises and answer their questions.
They must also establish an independent compliance function. Its head must report directly to the management body. The function must monitor DSA compliance, oversee risk mitigation and organise the independent audit.
Additional reporting for Reddit and Roblox: As VLOPs, Reddit and Roblox face an additional transparency requirement for content moderation, their reports must specify:
- The human resources devoted to content moderation in the EU, broken down by Member State language.
- The qualifications and linguistic expertise of those staff.
- Their training and support.
- Content-moderation accuracy indicators, broken down by official EU language.
All three must publish their DSA transparency reports within two months of the additional obligations taking effect and at least every six months thereafter. Their reports must also include average monthly recipients in each Member State.
Advertising and algorithmic transparency: If Reddit or Roblox displays advertisements, they must maintain a publicly accessible advertising repository. It must be searchable, support multiple criteria and provide an API. The repository must remain available while an advertisement runs and for one year afterwards.
It must include the advertisement, advertiser, payer, duration, targeting parameters, identified commercial communications and the number of recipients reached. It cannot contain recipients’ personal data. The same repository requirement applies to ChatGPT if it presents advertisements.
Oversight and penalties: The Commission can require these companies to provide access to databases and algorithms. It can also require them to retain documents needed to assess compliance and can appoint independent experts or auditors.
The Commission can impose a fineof up to 6% of worldwide annual turnover for an intentional or negligent DSA infringement. The same ceiling applies to breaches of interim measures or binding commitments.
It can impose a further fineof up to 1% of annual income or worldwide turnover for conduct such as providing incorrect or misleading information, failing to respond to information requests or refusing an inspection.
Furthermore, the Commission can also impose periodic penalty payments of up to 5% of average daily income or worldwide annual turnover per day. These can compel compliance with information requests, inspections, interim measures, binding commitments and enforcement decisions.
- EU Fines X 120 Million Euros For Flouting Digital Services Act
- EU tells Meta to change addictive design features or risk fines under DSA
